CVE-2023-28126
medium · 5.9An authentication bypass vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to gain access by exploiting the SetUser method or can exploit the Race Condition in the authentication message.
5.9
CVSS
66.7%
EPSS (exploit prob.)
99th
EPSS percentile
2023-05-09
Published
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-305CWE-362
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| ivanti | avalanche | <= 6.3.4.153 |
Check a specific version with /api/v1/cve/match.
References
- https://forums.ivanti.com/s/article/ZDI-CAN-17750-Ivanti-Avalanche-EnterpriseServer-GetSettings-Exposed-Dangerous-Method-Authentication-Bypass-Vulnerability?language=en_US
- https://forums.ivanti.com/s/article/ZDI-CAN-17750-Ivanti-Avalanche-EnterpriseServer-GetSettings-Exposed-Dangerous-Method-Authentication-Bypass-Vulnerability?language=en_US
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2023-28126